Topics I can contribute through consulting and training
Below are the areas where I can contribute through consulting and training. Each topic can be delivered as consulting or a training session, depending on the need.
Technical response during and after an incident: scoping, evidence collection, root cause analysis.
L1/L2/L3 incident response lifecycle: detection, triage, scoping, containment and escalation.
Behavior-based detection content for SIEM, EDR and custom platforms.
Hypothesis-driven proactive hunting to surface stealthy threats.
Deep scan of suspect or post-remediation environments for active intrusion and historical traces.
Static and dynamic analysis of suspect samples; behavior, IoC and family classification report.
Live testing and improvement of blue team detection capability against red team scenarios.
Building sector-specific CTI feeds and translating them into operational action.
I work in two formats: consulting and training, shaped by the request and the need. If you have a specific topic in mind, send a short email and let's talk.
Drop a short note describing what you have in mind; we can take it from there together.
Get in Touch →